

Isn’t the use of different random IP per request by bots a stronger arguments in favor of the default Anubis behavior? This would mean a lot of POW to be done by the bots.
The deep link accesses is worrying indeed and Anubis is not a silver bullet.
I also agree with the use of a known abusive IP database.


This seems to be exactly the content of the post: rate limit + Anubis.
The main point is more about “How to setup Anubis” rather than “Should we use Anubis” as I documented how I did my setup so I will not forget and at the same time sharing the resource. I am also using fail2ban but I didn’t feel a post about how to set ip up would be as useful as documentation and guides seems already there.